Impossible differentials in Twofish

Niels Ferguson

Twofish Technical Report #5, October 1999.

Abstract

We show how an impossible-differential attack, first applied to DEAL by Knudsen, can be applied to Twofish. This attack breaks six rounds of the 256-bit key version using 2256 steps; it cannot be extended to seven or more Twofish rounds.

Download

Zipped PostScript (47 kB)
PDF (125 kB)